A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Title | Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-29T19:28:43.201Z
Reserved: 2026-08-19T16:13:18.140Z
Link: CVE-2026-76728
No data.
Status : Received
Published: 2026-09-29T20:17:24.947
Modified: 2026-09-29T20:17:24.947
Link: CVE-2026-76728
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.